DocumentCode :
1924467
Title :
Mitigation of application DDoS attacks using ASNRI scheme for IP and MAC frames
Author :
Prabha, S. ; Anitha, R.
Author_Institution :
R&D Centre, Bharathiar Univ., Coimbatore, India
fYear :
2013
fDate :
21-22 Feb. 2013
Firstpage :
204
Lastpage :
209
Abstract :
With increasing trend in application services on large-scale internet scenario of both wired and wireless interface, intimidation to restrain the application service by Distributed Denial of Service (DDoS) attacks become a high-flying issue. Most of the present DDoS attacks resistance method work on application services in wired network and wireless network individually. No method is offered herewith for the two kinds of networks up to now. Though the present internet application services must switch between wired and wireless platform, well-matched resistance method for Distributed Denial of Service attacks have to be coined for better security which is the present requirement in the environment. With these issues in mind, the proposed model develops counter mechanism to mitigate the potency of the resource attacks and evaluate the efficacy. Application Service Network Request Identification (ASNRI) scheme is presented to provide an apparent demarcation of wired service and wireless services request, which is then fed to the Bayes packet classifier for its associated denial of service attack characteristics. From the Bayes packet classifier, resistance filters are stimulated to restrict denial of service attacks in the respective platform, that is., wired or wireless. The simulation of the proposed ASNRI scheme is conducted with NS-2 simulator to show its effectiveness of restricting Distributed Denial of Service attacks in terms of RESPONSE TIME, APPLICATION SERVICE THROUGHPUT, LOAD VARIANCE in the application server.
Keywords :
Internet; computer network security; pattern classification; protocols; ASNRI scheme; Bayes packet classifier; DDoS attack resistance method; IP frame; Internet protocol; MAC frame; NS-2 simulator; application DDoS attack mitigation; application service; application service network request identification; application service throughput; distributed denial-of-service attack; large-scale Internet scenario; load variance; medium access control; response time; wired network; wireless network; Computer crime; Entropy; Hidden Markov models; IP networks; Resistance; Servers; Throughput; Am; Bayes Packet Classifier and Gaussian Distribution; Hmm; IP and MAC frames;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Pattern Recognition, Informatics and Mobile Engineering (PRIME), 2013 International Conference on
Conference_Location :
Salem
Print_ISBN :
978-1-4673-5843-9
Type :
conf
DOI :
10.1109/ICPRIME.2013.6496473
Filename :
6496473
Link To Document :
بازگشت